Back to directory
WRITEUP #1129

Hunting For Password Reset Tokens By Spraying And Using HTTP Pipelining

Auth BypassPassword resetAccount takeover
byTom Neaves
Program
-
Published
May 30, 2023
Added to HackDex
Jun 1, 2023
Read Full Writeuphttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hunting-for-password-reset-tokens-by-spraying-and-using-http-pipelining/
RELATED WRITEUPS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center
Auth Bypass2FA / MFA bypass
Forced SSO Session Fixation
Auth BypassSSO
Account takeover on 8 years old public program
Auth BypassAccount takeover
Breaking the Barrier: Admin Panel Takeover Worth $3500
Auth BypassAuthentication bypass

Built with ❤️ by Shubham Rawat